CVE-2022-22652 describes a vulnerability in Apple iOS and iPadOS where the GSMA authentication panel could be accessed and modified from the lock screen. This medium-severity flaw (CVSS 6.1) allowed an attacker with physical access to view and alter carrier account information and settings without device unlock. While the potential impact was high for confidentiality and integrity, the attack required physical proximity and low complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability, which has been patched in iOS 15.4 and iPadOS 15.4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.4CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.